CREST Launches AI Pentesting Accreditation
10 firms earn CREST's new AI-Enabled Penetration Testing accreditation, setting a governance standard.
CREST, the cybersecurity industry body, has announced the first 10 companies to receive its new accreditation for the responsible use of AI in penetration testing. The accreditation, integrated into CREST's Penetration Testing Accreditation Standard in July 2026, marks a significant step in formalizing AI governance within offensive security services.
First Cohort Announced
The inaugural cohort includes firms spanning Europe, India, and the US: Closed Door Security Ltd, ImmuniWeb, JUMPSEC Ltd, Packetlabs, Pentesys, REDSECLABS Private Ltd, Risk Associates, SECNORA OÜ, Solusec Ltd, and Thoropass Inc. These providers have undergone independent assessment to demonstrate that their integration of AI into daily operations meets CREST's standards for responsible and secure AI governance.
Optional Module, Not a Requirement
The new AI-Enabled Penetration Testing accreditation is an optional module, meaning standard CREST memberships are unaffected. However, providers who actively use AI can now seek this additional verification, offering clients and regulators an extra layer of assurance beyond voluntary claims. This distinction ensures the accreditation serves as a supplementary badge of credibility rather than a replacement for existing standards.
Industry Leaders Weigh In
William Wright, CEO of Closed Door Security, emphasized the impact of AI on pentesting, stating it is “helping security teams work more efficiently at scale, and identify vulnerabilities faster.” He added, “However, it needs to be governed appropriately. Closed Door Security is proud to be part of the first CREST cohort to be accredited for AI-Enabled Penetration Testing, ensuring the technology is adopted safely to genuinely benefit and improve the security of organizations.”
Denis Kucinic, VP Operations at Packetlabs, echoed the sentiment, noting that “AI will be revolutionary for security providers like Packetlabs, but it's vital that we assure customers, and the wider industry, that it's being deployed and used responsibly. Accreditation providers like CREST help companies do exactly that. With independent and assessable standards, providers can back up voluntary promises with concrete assurance.”
CREST's Roadmap to AI Assurance
The accreditation builds on CREST's AI in Penetration Testing report, released in March 2026, which found that over three-quarters (76%) of cybersecurity providers have increased their AI usage over the past year, with 69% already integrating it into daily service delivery. These statistics highlight the rapid adoption of AI in the field, underscoring the need for governance mechanisms to keep pace.
Following the report, CREST published a set of AI Principles in March and an AI Charter in June, which was publicly signed by over 100 cybersecurity organizations. The accreditation module now translates these principles into a formal, assessable framework.
Governance Meets Practice
Nick Benson, CEO of CREST, said the AI additions help the industry “move from discussion and principles around AI towards independently assured, responsible adoption.” This progression from voluntary principles to an auditable accreditation demonstrates CREST's commitment to turning high-level commitments into practical standards.
Why It Matters
The introduction of this accreditation could signal a shift in how AI is governed in cybersecurity. As more providers integrate AI into their services, having a standardized, independently verified mark of responsible use may become a key differentiator in the market. For clients, it offers a new benchmark for evaluating penetration testing partners, potentially influencing procurement decisions. For the industry, this move suggests that AI governance is moving beyond discussion into enforceable, auditable practice — a development that may set a precedent for other areas of cybersecurity.
Sources
- Infosecurity Magazine Original source
Continue Reading
Plex urges urgent patching
Plex warns users to update Media Server and Desktop clients to fix multiple undisclosed security flaws.
ARM Windows users hit by Teams, Outlook launch failures
Microsoft confirms August 2026 updates break Teams and Outlook on ARM devices; workaround available.
Zero trust meets its agentic AI reckoning
Autonomous agents strain zero trust's identity limits, experts warn as adoption lags.